Skip to main content
drupalreleases
Release: Cms 2.2.3 — Update released for Drupal core (2.2.3)! Release: Easy Breadcrumb 2.0.11 — Minor update available for module easy_breadcrumb (2.0.11). Release: Bootstrap 8.x-3.42 — Minor update available for theme bootstrap (8.x-3.42). Release: Editoria11y Accessibility Checker 3.0.10 — Minor update available for module editoria11y (3.0.10). Release: Editoria11y Accessibility Checker 2.2.24 — Minor update available for module editoria11y (2.2.24). Release: Leaflet 10.4.13 — Minor update available for module leaflet (10.4.13). Release: Flag 5.1.1 — Minor update available for module flag (5.1.1). Release: Layout Paragraphs 3.0.0-beta5 — New beta version released for module layout_paragraphs (3.0.0-beta5). Module Revived: Bootstrap 8.x-3.41 — Theme bootstrap updated after 6 months of inactivity (8.x-3.41). Security Coverage: Component Library — Module component_library now has official Drupal security advisory coverage.

Cybersource SOP

Security covered Drupal 10–11
View on drupal.org

This module integrates Drupal Commerce with Cybersource Secure Acceptance in Silent Order POST mode, allowing shoppers to enter payment details directly on your website's checkout page. Card information is securely sent from the shopper's browser straight to Cybersource, never touching your server, and the payment is verified before being recorded.

Cybersource SOP lets a Drupal Commerce shop take credit and debit card payments through Cybersource, using Cybersource Secure Acceptance in Silent Order POST (SOP) mode. Shoppers enter their card details on your own styled checkout page, but the card data is sent straight from their browser to Cybersource and never touches your server. Cybersource returns a digitally signed result, which the module verifies before recording the payment against the order.

Features

Adds a Cybersource (Secure Acceptance SOP) payment gateway to Drupal Commerce. Use it when you run Drupal Commerce, your processor is Cybersource, and you want card fields on your own checkout (rather than a hosted redirect) while keeping card data off your server.

  • Polished on-page card form with live brand detection (Visa, Mastercard, Maestro, American Express, Discover, Diners Club, JCB) and inline Luhn, expiry and CVV validation — no card-type dropdown.
  • Card number and CVV are POSTed directly from the browser to Cybersource; your server never receives or stores them.
  • Replies are rejected unless their HMAC-SHA256 signature verifies, and every field the payment logic acts on must be covered by that signature.
  • The recorded payment amount and currency always come from the order, never from the returned POST (fail-closed on any mismatch).
  • Replay guard: the same Cybersource transaction is never recorded twice.
  • Supports Authorization and Sale (authorize + capture) transaction types.
  • Decision Manager review outcomes are recorded as a pending authorization and the order is held, not auto-completed.
  • Multi-currency credentials: one test profile for all currencies, one live profile per currency.
  • Security-key expiry monitoring on the Status report, warning you before a key expires.
  • Every gateway response is written to the order audit log (never card data).

Post-Installation

There is no new content type — configuration is the gateway settings plus an external credentials file. Credentials are deliberately kept out of Drupal configuration (never written to the database or exported to config).

  1. Configure Drupal's private filesystem (the file_private_path setting in settings.php), pointing it at a directory outside the web root.
  2. Copy cybersource.credentials.example.yml to private://keys/cybersource.yml, fill in your Secure Acceptance profile values (profile_id, access_key, secret_key), and make it readable by the web server user only.
  3. Go to Administration » Commerce » Configuration » Payment gateways and add a "Cybersource (Secure Acceptance SOP)" gateway; set the mode (test or live), transaction type and locale. The gateway panel reports whether the credentials file is present.
  4. In the Cybersource Business Center, on the matching Secure Acceptance profile: choose the Silent Order POST integration method, enable card payments and your currencies, allow the merchant to override the customer response page, then activate the profile and generate a security key.

Additional Requirements

  • Drupal Commerce — the commerce_payment, commerce_order, commerce_price, commerce_log,
    commerce_cart and commerce_checkout sub-modules.
  • A Cybersource Secure Acceptance Silent Order POST profile (profile_id / access_key / secret_key) for each environment and currency you take payments in.
  • Drupal's private file system configured.

No third-party PHP libraries are required; request signing uses PHP's built-in hash_hmac().

None are required. Because Silent Order POST renders card fields in your checkout pld serve a strict Content-Security-Policy on checkout pages and lockdown who can inject markup. A security-header module such as Security Kit (SecKit) can help you set this up.

Similar projects

Commerce CyberSource Flex Microform (iframe-hosted fields over the REST API). This module instead usesSecure Acceptance Silent Order POST, keeps credentials in the private filesystem (resolved per mode and currency) rather than in site configuration, and ships an on-page card form with live validation. Choose this module if you specifically want the Secure Acceptance SOP flow.

Supporting this Module

Maintained by Graith Internet. Please file bug reports and feature requests in the project's issue queue.

Community Documentation

Full configuration, security-hardening and testing notes are in the module's mo and walkthrough may be linked here later.)

PCI scope

Because Silent Order POST renders card fields in your checkout page, your card-data environment is typically assessed as PCI DSS SAQ A-EP (not the lighter SAQ A used by hosted-page or iframe integrations). Confirm your PCI scope and SAQ eligibility witnd and/or QSA. This module is not a PCI compliance tool and ships no official PCIcontent.

Depends on

Dependencies of the latest stable release

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
4
Tracked since
Jun 2026
Latest release
1 month ago
Releases (12 mo)
4 ▲ from 0
Maintenance
Active

Release Timeline

Releases

Version Type Core Release date
1.0.2 Stable 10–11 Sep 5, 2026
1.0.1 Stable 10–11 Jul 1, 2026
1.0.0 Stable 10–11 Jun 30, 2026
1.0.x-dev Dev 10–11 Jun 30, 2026